277
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 13 Jun 2026
277 points (100.0% liked)
Technology
85748 readers
3293 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
Haven't seen an arch fuckup like this since they switched to signed packages.
This is not ArchLinux' fuckup. The AUR's popularity exploded after certain Arch-based distros (and software) decided to treat the AUR as an additional software repository, even part of package management, and automate the process of installation. Which also slows the process of discovering the malware. And makes panicky users wave their arms.
May I remind everyone of Arch core principles and statements wrt AUR - several quotes from their wiki:
Note how the crucial PKGBUILD is mentioned in the first sentence, and dozens of times in the article that follows.
The AUR even includes PGP signing; not perfect, but a useful additional step. But, alas, many AUR helpers include "skip PGP check".
Archlinux devs, maintainers and users have been saying this for over a decade, and warning against using the AUR in such ways. But short of shutting the whole thing down, what can they do? The few things that can reasonably be done I'm sure are being implemented right now.
Ah now I read this far. Unfortunate, if easy to use Archy distros are un-Archy due to this political dispute that goes undisclosed.
It doesn't sound like their victims are panicky users, though. Sounds like their normal computer users, the kind of person who would typically want use Windows instead. The kind of people who are, and should be safe to remain, totally agnostic to these internal political divides.
"Political"?! 🤪
As in "office politics" or "workplace politics," yes
I wouldn't really categorise it as a fuckup. These are unofficial packages from the AUR. You should trust them as much as random install scripts from a no-name website or git repo.